Privacy Policy

This policy explains what personal information Westorably collects, why we collect it, who we share it with, how long we keep it and what you can do about it. It covers our website, our marketing, and the Westorably application used by storage facility operators and their tenants.

Effective 27 July 2026 Last updated 27 July 2026 Applies worldwide

The one line that matters: we do not sell your data, we do not sell your tenants' data, and we never see or store card numbers. Payment details go directly to Stripe.

1. Who we are

Westorably provides self-storage management software. In this policy, “Westorably”, “we”, “us” and “our” mean [LEGAL ENTITY NAME, e.g. Westorably LLC], a company registered at [REGISTERED ADDRESS].

“Operator” or “Customer” means a business that subscribes to the Westorably application to run one or more storage facilities. “Tenant” means an individual or business that rents a storage unit from an Operator and interacts with a booking page or tenant portal powered by Westorably. “You” means whichever of these applies to you, and also anyone who simply visits our website.

Our data protection contact is privacy@westorably.com.

2. The short version

QuestionAnswer
Do you sell personal information?No. We do not sell or share personal information for cross-context behavioural advertising.
Do you store card numbers?No. Card data is captured by Stripe in fields we cannot read, and is stored by Stripe.
Who owns the tenant data in the app?The Operator. We process it on their instructions under our Data Processing Addendum.
Do you use my data to train AI models?No. We do not use Customer Data or tenant personal information to train generative AI models, and we do not permit our sub-processors to do so.
Can I get my data deleted?Yes. See section 12.
Where is data stored?Primarily in the United States, with safeguards described in section 9.

3. When we are a controller and when we are a processor

This distinction changes who you should contact about your data.

  • We are a controller for information about our website visitors, prospective customers, Operator account holders, billing contacts and support correspondents. We decide why and how that information is used, and this policy governs it.
  • We are a processor for the tenant records, leases, documents and payment histories that an Operator loads into or generates inside the application. The Operator is the controller. We act on their documented instructions under the Data Processing Addendum.

If you are a storage tenant and you want to access, correct or delete your records, contact the facility you rent from. If they ask us to act, we will. We will also forward requests we receive directly, where we can identify the relevant Operator.

4. Information we collect

4.1 Information you give us

  • Account details: name, business name, email address, phone number, password (stored only as a salted hash), role and time zone.
  • Facility details: facility name, address, unit inventory, sizes, rates, operating hours and photographs.
  • Billing details: billing name, billing address, tax identifiers, and the last four digits, brand and expiry of the payment method. Full card numbers are handled by Stripe, not by us.
  • Support and sales content: the contents of emails, call notes, demo requests and any files you send us, including migration spreadsheets.
  • Marketing preferences: subscription status and interaction with our emails.

4.2 Information collected automatically

  • Device and connection data: IP address, browser type and version, operating system, screen size, language and referring URL.
  • Usage data: pages viewed, features used, timestamps, and error and performance diagnostics.
  • Security logs: sign-in attempts, IP addresses used for authentication, and records of sensitive actions taken inside an account.
  • Cookies and similar technologies: see section 7 and our Cookie Policy.

4.3 Tenant information we process for Operators

When an Operator uses the application, we process information about their tenants on their behalf. This typically includes name, postal address, email address, telephone number, unit assignment, lease dates and terms, rental rate, payment and arrears history, gate or lock access events where smart lock integration is enabled, uploaded identity documents, insurance details and free-text notes written by the Operator.

Operators decide what to upload. We ask Operators not to place special category data (such as health information) into free-text fields, because the product is not designed for it.

4.4 Information from other sources

  • Stripe: payment status, payout status, dispute and chargeback notifications, and limited identity verification results required for anti-money-laundering compliance.
  • Business data providers and public sources: for sales outreach we may use publicly available business contact details such as a facility's listed phone number, website or a role-based email address.
  • Integration partners: where an Operator connects a smart lock or gate system, we receive device, unit and access event data from that vendor's API.

5. How and why we use information

  • To provide the service: create and secure accounts, display unit maps, generate leases, run recurring charges, send reminders and receipts, and produce reports.
  • To take payment: bill subscriptions and add-ons, and pass instructions to Stripe so an Operator can collect rent from tenants.
  • To support you: answer questions, migrate your data during onboarding, and investigate faults.
  • To keep the service safe: detect fraud, abuse, credential stuffing and unauthorised access, and enforce our Acceptable Use Policy.
  • To improve the product: understand which features are used, diagnose performance problems, and prioritise work. We use aggregated and de-identified data for this wherever it is sufficient.
  • To communicate: send service notices, security alerts, billing notices and, where permitted, product and marketing email you can unsubscribe from at any time.
  • To comply with law: meet tax, accounting, sanctions and lawful request obligations, and establish or defend legal claims.

We do not use Customer Data or tenant personal information to train generative artificial intelligence models. Where the product uses automated processing, for example flagging an account as overdue, it is rule-based and configured by the Operator.

6. Legal bases (EEA, UK and Switzerland)

PurposeLegal basis
Providing the service to an OperatorPerformance of a contract
Billing, invoicing and collectionsPerformance of a contract; legal obligation
Security, fraud prevention and abuse detectionLegitimate interests in protecting the service and its users
Product analytics and improvementLegitimate interests in improving a service people rely on
Business-to-business marketing emailLegitimate interests, or consent where local law requires it
Non-essential cookiesConsent
Tax, accounting and record-keepingLegal obligation

Where we rely on legitimate interests we have assessed that our interest does not override your rights. You can object at any time using the contact details in section 17.

7. Cookies and similar technologies

We use a small number of cookies. Strictly necessary cookies keep you signed in, remember your consent choice and protect forms against cross-site request forgery; these cannot be switched off. Analytics cookies, if enabled, help us understand which pages are useful and are only set with your consent where consent is required. We do not run advertising or cross-site tracking cookies.

Full detail, including names, purposes and lifetimes, is in the Cookie Policy. You can change your choice at any time there, or through your browser settings. We honour the Global Privacy Control signal where it is legally recognised.

8. When we share information

We do not sell personal information. We share it only in these situations:

  • Service providers (sub-processors): hosting, database, email delivery, SMS delivery, payment processing, error monitoring and customer support tools. Each is bound by contract to process data only on our instructions and to protect it. The current list is published at westorably.com/subprocessors.
  • Between an Operator and their tenants: the application is designed to show an Operator their own tenants' records. Operators never see another Operator's data.
  • Integration partners you connect: if you enable a smart lock, gate, accounting or other integration, data flows to that vendor under their own privacy terms.
  • Professional advisers: lawyers, accountants and auditors, under confidentiality obligations.
  • Corporate transactions: in a merger, acquisition, financing or sale of assets, subject to this policy continuing to apply to the transferred information.
  • Legal requirements: where we are required by law, court order or valid legal process, or where disclosure is necessary to protect rights, safety or property. We will notify affected customers of a legal demand unless we are prohibited from doing so.

9. International transfers

We are a global service. Personal information is primarily stored and processed in the United States, and may also be processed in the European Union and in other countries where our sub-processors operate, including where our team is located.

Where we transfer personal information out of the European Economic Area, the United Kingdom or Switzerland, we rely on appropriate safeguards, which currently include the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and adequacy decisions where they apply. We carry out transfer risk assessments and apply encryption in transit and at rest as supplementary measures. You can request a copy of the relevant safeguards by emailing privacy@westorably.com.

10. How long we keep information

CategoryRetention
Operator account and facility dataFor the life of the subscription, then 30 days for export, then deletion within a further 60 days
Tenant records processed for an OperatorPer the Operator's instructions and the DPA; deleted or returned on termination
Invoices, tax and accounting recordsUp to 7 years, or longer where local law requires
Security and authentication logsUp to 12 months
Support correspondenceUp to 3 years after the last message
Marketing contact recordsUntil you unsubscribe, plus a suppression record kept indefinitely so we do not contact you again
BackupsRolling 35-day cycle; deleted records disappear from backups as the cycle rotates

11. How we protect information

  • Encryption in transit using TLS 1.2 or above, and encryption at rest using AES-256.
  • Card data handled exclusively by Stripe, a PCI DSS Level 1 service provider. Westorably systems never receive full card numbers.
  • Role-based access control inside the product, so staff at a facility see only what their role requires.
  • Least-privilege internal access, multi-factor authentication for administrative systems, and logging of privileged actions.
  • Automated daily backups with point-in-time recovery, stored separately from production.
  • Dependency scanning, security patching and periodic review of our infrastructure configuration.

No system is perfectly secure. If a personal data breach affects you, we will notify you and the relevant supervisory authority as required by law, and for Operators within the timeframe set out in the DPA. To report a suspected vulnerability, email security@westorably.com. We will not pursue legal action against good-faith security research that respects user privacy and does not degrade the service.

12. Your rights

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you and receive a copy.
  • Correct information that is inaccurate or incomplete.
  • Delete information, subject to legal retention obligations.
  • Receive your information in a portable, machine-readable format, or have it transmitted to another provider.
  • Restrict or object to certain processing, including direct marketing.
  • Withdraw consent at any time, without affecting processing already carried out.
  • Complain to a supervisory authority. In the EEA this is the authority in your country of residence; in the UK it is the Information Commissioner's Office.

To exercise a right, email privacy@westorably.com. We will verify your identity proportionately, usually by confirming control of the email address on the account, and respond within 30 days, or within the period your local law requires. We do not charge a fee unless a request is manifestly unfounded or excessive, and we will not discriminate against you for exercising a right.

Operators can satisfy most requests themselves: the application includes edit, delete and one-click CSV export for units, tenants and payments.

13. Additional rights for US state residents

If you are a resident of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana or another state with a comprehensive privacy law, you have the rights described in section 12, and additionally the right to opt out of sale, sharing for cross-context behavioural advertising, and profiling that produces legal or similarly significant effects.

We do not sell or share personal information in the sense those laws use, and we do not conduct such profiling. We therefore have no opt-out mechanism to offer, but we honour Global Privacy Control signals where recognised.

Categories of personal information collected in the last 12 months, using California's terminology: identifiers; customer records; commercial information; internet and network activity; geolocation inferred from IP address at city level; and, where an Operator uploads them, government identifiers contained in tenant identity documents. Purposes and disclosures for each are described in sections 4, 5 and 8. You may designate an authorised agent to make a request on your behalf with proof of authorisation.

14. Children

The service is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with information, contact privacy@westorably.com and we will delete it.

15. Automated decision-making

We do not carry out automated decision-making that produces legal or similarly significant effects on individuals without human involvement. Rules configured by an Operator, such as automatically suspending gate access after a set number of overdue days, are the Operator's decisions, applied by our software on their instruction. Operators can override any such action manually.

16. Changes to this policy

We may update this policy as the product or the law changes. When we make a material change we will update the “last updated” date, and notify Operators by email or an in-product notice at least 14 days before it takes effect. Continuing to use the service after the effective date means you accept the updated policy. Previous versions are available on request.

17. Contact us

Privacy questions, rights requests and complaints: privacy@westorably.com
Security reports: security@westorably.com
General enquiries: hello@westorably.com

Postal address: [REGISTERED ADDRESS]
EU/UK representative under Article 27, where required: [EU/UK REPRESENTATIVE, or delete this line]

Related documents: Terms of Service · Cookie Policy · Data Processing Addendum · Sub-processors · Acceptable Use Policy